Privacy Policy
This policy explains how personal data is handled through the CRS website and scoped CrisisReadinessCheck interactions.
Last updated: September 2026
Controller Identity
Controller: Tom De Wilde, sole proprietor
Address: Chrysantenlaan 2, 1740 Ternat, Belgium
Enterprise no.: 0846.629.064
VAT: BE 0846.629.064
Privacy contact: tom@myrealitycheck.ai
MyRealityCheck.ai is a brand and website operated by Tom De Wilde.
What We Collect and Why
| Data | Purpose | Legal basis |
|---|---|---|
| Organisation and contact details | To administer CRS interactions, confirm receipt and communicate about the agreed CRS process. | Legitimate interest; contract performance where applicable |
| CRS assessment responses | To record self-report input for scoped CRS review and, where authorised, report preparation. | Contract performance where applicable; legitimate interest |
| Open-response input | To provide contextual input for the scoped CRS review. | Contract performance where applicable; legitimate interest |
| Usage data | To operate and secure the CRS website and understand aggregate website usage. | Legitimate interest |
What Not to Submit Through the CRS Website
The public CRS website does not provide a document-upload route for supporting evidence. Do not submit classified information, unnecessary personal data, special-category personal data, unnecessary technical or operational secrets, or source documents through the public website.
Where supporting evidence is required for an agreed CRS engagement, it is handled separately through the approved engagement-specific evidence channel and within the agreed scope. Source evidence is not an authorised input to the consumer-AI support route.
How We Use CRS Personal Data
We use CRS personal data only for the purposes described in this policy, including operating and administering CRS, conducting the agreed review, communicating with you, securing the service and understanding aggregate website usage.
We do not sell CRS personal data or share it with other clients. Personal data may be processed by service providers used to operate CRS, store assessment input, host the website, provide aggregate analytics and, if separately enabled, deliver transactional email.
AI-Assisted Report Production
CRS may use AI as a bounded support layer during report production. Deterministic CRS scores are calculated outside AI and are not calculated, altered or approved by an AI system.
The current consumer-AI handoff excludes organisation identity, contact identity and contact details, location, raw crisis-context input, raw domain open responses and source documents or evidence. Only bounded pseudonymised organisation-profile information and deterministic score data may enter that route. Any qualitative excerpt must first be reviewed and sanitised by a human under the approved workflow.
AI output is not evidence and does not itself constitute a CRS conclusion. Evidence interpretation, challenge, judgment, report approval and release remain human responsibilities.
Retention
CRS applies category-specific retention rules rather than retaining customer data indefinitely. The current MRC operating policy uses the following default periods, subject to any documented legal hold, active dispute, executed customer requirement or later professionally confirmed obligation.
- Quick Scan identifiable data: 12 months from submission.
- Full CRS assessment data: 24 months after engagement close or last substantive CRS activity, whichever is later.
- Generated final reports: 5 years after final delivery.
- Supplied evidence, SOPs and source material: returned or deleted within 90 days after final delivery or engagement close, whichever is later.
- Routine application/security logs: 90-day rolling retention where MRC can configure it; provider-controlled retention may differ.
These are MRC operating periods and are not presented as statutory minimums. Data is deleted, anonymised or returned when the applicable period or closure trigger is reached, subject to documented exceptions.
Service Providers and International Processing
CRS currently uses Supabase for database and authentication services, Netlify for website hosting and server-side application processing, and Plausible for privacy-focused aggregate analytics.
The current CRS Supabase project is hosted in eu-west-1 (Ireland). The current Netlify server runtime used by CRS is in the United States (US East / Ohio), so CRS processing is not EU-only. Plausible states that its visitor analytics data is processed and stored in the EU.
CRS code also supports optional transactional email delivery through Resend. No active Resend runtime credential was present in the verified production configuration at the time of the latest review, so Resend is not represented here as active current processing. If that processing is enabled, this policy and the current provider register will be updated to reflect the actual data flow and applicable safeguards.
Where processing outside the EEA requires a transfer mechanism or other safeguards, MRC uses only safeguards applicable to the relevant provider and processing activity. The detailed legal assessment of those safeguards is subject to the applicable provider terms and, when the CRS buyer process triggers it, a bounded professional privacy review.
Cookies and Aggregate Analytics
CRS uses essential cookies where required for the website or assessment flow to function. CRS also uses Plausible for privacy-focused aggregate analytics.
We do not intentionally send names, emails, organisation names, scan answers, scores, submission IDs, access-grant identifiers or evidence content to analytics. We do not use advertising cookies, cross-site tracking, session replay or fingerprinting.
Your Rights
Under GDPR, you may have the right to:
- AccessRequest a copy of personal data held about you.
- RectifyAsk for inaccurate data to be corrected.
- EraseAsk for deletion where the GDPR conditions are met.
- RestrictAsk for processing to be restricted where applicable.
- ObjectObject to processing based on legitimate interest.
- PortabilityReceive data in a structured format where applicable.
To exercise these rights, contact tom@myrealitycheck.ai.
We will respond to GDPR rights requests without undue delay and in principle within one month, subject to the extensions and other conditions permitted by GDPR.
Complaints
You may lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorite de protection des donnees).
Updates to this Policy
This Privacy Policy was last updated in September 2026.
We may update this Privacy Policy when CRS processing changes. The current CRS Privacy Policy is available at crs.myrealitycheck.ai/privacy. Where required by law, we will provide additional notice of material changes.